Implantable Cardiac Devices Could Be Vulnerable To Hackers, FDA Warns

The U.S. Food and Drug Administration warned on Monday that pacemakers, defibrillators and other devices manufactured by St. Jude Medical, a medical device company based in Minnesota, could have put patients’ lives at risk, as hackers could remotely access the devices and change the heart rate, administer shocks, or quickly deplete the battery. Thankfully, St. Jude released a new software patch on the same day as the FDA warning to address these vulnerabilities. Motherboard reports: St. Jude Medical’s implantable cardiac devices are put under the skin, in the upper chest area, and have insulated wires that go into the heart to help it beat properly, if it’s too slow or too fast. They work together with the [email protected] Transmitter, located in the patient’s house, which sends the patient’s data to their physician using the Merlin.net Patient Care Network. Hackers could have exploited the transmitter, the manufacturer confirmed. “[It] could (…) be used to modify programming commands to the implanted device,” the FDA safety communication reads. In an emailed response to Motherboard, a St. Jude Medical representative noted that the company “has taken numerous measures to protect the security and safety of our devices,” including the new patch, and the creation of a “cyber security medical advisory board.” The company plans to implement additional updates in 2017, the email said. This warning comes a few days after Abbott Laboratories acquired St. Jude Medical, and four months after a group of experts at Miami-based cybersecurity company MedSec Holding published a paper explaining several vulnerabilities they found in St. Jude Medical’s pacemakers and defibrillators. They made the announcement at the end of August 2016, together with investment house Muddy Waters Capital.